Sign in | Join United States - English [Change]
 Home > Insights 

This Blog

Syndication

Calendar

<September 2006>
SunMonTueWedThuFriSat
272829303112
3456789
10111213141516
17181920212223
24252627282930
1234567

CA Security Advisor Research Blog

Find out what our research team is saying about the latest security threats in the CA Security Advisor blog

VML Exploit

A vulnerability was recently discovered in Microsoft Windows Vector Markup Language (VML). This issue allows an attacker to execute malicious code through an HTML page in Internet Explorer, or in an HTML formatted email. Sunbelt first found and reported this exploit on September 18, 2006, after finding samples in the wild.

 

The CA Security Advisor team has observed malware that utilizes this vulnerability to drop a payload that includes device drivers with rootkit-like behavior. Research is continuing, and more details will be posted on the Security Advisor Research Blog as they become available.

 

On September 19, 2006, Microsoft published a security advisory at URL http://www.microsoft.com/technet/security/advisory/925568.mspx stating that a vulnerability in the Microsoft Windows implementation of Vector Markup Language could allow remote code execution. At the time, Microsoft is planning to release a security update on October 10, 2006 for the affected operating systems.

 

To protect against this exploit, unregister vgx.dll (the dll with the vulnerability) by clicking on Start and then Run and typing the following command:

 

Regsvr32 /u "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"

Share this post: Email it! | bookmark it! | digg it! | reddit!

Comments

No Comments

About Nancy Strutt

Nancy Strutt is a Senior Researcher with CA's PestPatrol Spyware Research Team. She received a B.S. in Computer Science and Communication Studies from the University of Maryland, as well as a M.S. in Information Systems Management from Capitol College. Her particular areas of interest in spyware research include rootkits and advertising networks. Before joining PestPatrol she developed software and web applications.
 
 
Page Tools